Citrix NetScaler critical flaw could leak data, update now

2026-03-24T14:51:55Zcf260d78b87e847748a7d80d710de76034f5de93bfeed42a94bc77b260abc998
Aqua SecurityCVE-2025-62843CVE-2025-62844CVE-2025-62845CVE-2025-62846CVE-2026-21992CVE-2026-3055Citrix NetScalerDocker HubIran-linkedNasir SecurityNorth Korea-linkedOracle Identity ManagerQNAPRussia-linked actors vs messaging apps','Operation Alice','dark‑Signal phishingStoatWaffleTeam 8TeamPCPTelegram C2TrivyVisual Studio CodeWhatsApp phishinginfostealersupply chain

What happened

Multiple high-impact security stories: Citrix issued an urgent patch for a critical NetScaler memory overread (CVE-2026-3055, CVSS 9.3) that can leak sensitive data; Oracle fixed a critical unauthenticated RCE in Identity Manager/Web Services Manager (CVE-2026-21992, CVSS 9.8). QNAP addressed four vulnerabilities demonstrated at Pwn2Own (CVE-2025-62843 → CVE-2025-62846). Other incidents include a Trivy/Docker Hub supply-chain compromise that pushed TeamPCP infostealer code and defaced Aqua Security repositories, North Korea-linked actors abusing VS Code auto-run to spread StoatWaffle, Iran- or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
cf260d78b87e847748a7d80d710de76034f5de93bfeed42a94bc77b260abc998
Enrichment time
2026-03-24T14:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.